Organization Policy MCP Server provides tools to discover, manage, and audit organization policies and custom constraints across Google Cloud resources.
A Model Context Protocol (MCP) server acts as a proxy between an external service that provides context, data, or capabilities to a Large Language Model (LLM) or AI application. MCP servers connect AI applications to external systems such as databases and web services, translating their responses into a format that the AI application can understand.
Server Setup
You must enable MCP servers and set up authentication before use. For more information about using Google and Google Cloud remote MCP servers, see Google Cloud MCP servers overview.
Server Endpoints
An MCP service endpoint is the network address and communication interface (usually a URL) of the MCP server that an AI application (the Host for the MCP client) uses to establish a secure, standardized connection. It is the point of contact for the LLM to request context, call a tool, or access a resource. Google MCP endpoints can be global or regional.
The Organization Policy API MCP server has the following global MCP endpoint:
- https://orgpolicy.googleapis.com/mcp
MCP Tools
An MCP tool is a function or executable capability that an MCP server exposes to a LLM or AI application to perform an action in the real world.
Tools
The orgpolicy.googleapis.com MCP server has the following tools:
| MCP Tools | |
|---|---|
ListConstraints |
Lists constraints that can be applied to a specific resource (project, folder, or organization). Use this to discover what constraints are available to enforce. |
ListPolicies |
Retrieves all explicit policies set on a particular resource. Useful for auditing what policies are directly applied. |
GetPolicy |
Gets a specific policy on a resource by name. Returns the policy details if set. |
GetEffectivePolicy |
Gets the final, evaluated policy on a resource, taking into account inheritance from parent resources and conditions. Use this to see the actual enforcement state. |
CreatePolicy |
Creates a new policy on a resource to enforce specific constraints. |
UpdatePolicy |
Updates an existing policy on a resource. Note that this performs a full overwrite of the policy. |
DeletePolicy |
Deletes a policy from a resource, causing it to inherit policies from its parent or revert to the default constraint behavior. |
CreateCustomConstraint |
Creates a new custom constraint for an organization, allowing for fine-grained resource restriction using CEL. |
UpdateCustomConstraint |
Updates an existing custom constraint. Note that this performs a full overwrite. |
GetCustomConstraint |
Gets the definition of a custom or managed constraint by name. |
ListCustomConstraints |
Lists all custom constraints defined for an organization. |
DeleteCustomConstraint |
Deletes a custom constraint from an organization. |
Get MCP tool specifications
To get the MCP tool specifications for all tools in an MCP server, use the tools/list method. The following example demonstrates how to use curl to list all tools and their specifications currently available within the MCP server.
| Curl Request |
|---|
curl --location 'https://orgpolicy.googleapis.com/mcp' \ --header 'content-type: application/json' \ --header 'accept: application/json, text/event-stream' \ --data '{ "method": "tools/list", "jsonrpc": "2.0", "id": 1 }' |